Favicon of Workday

IAM/IGA Engineer

at Workday

The IAM/IGA Engineer is responsible for designing, implementing, supporting, and maintaining identity security solutions that ensure secure access to enterprise resources. This role focuses on identity lifecycle management, privileged access management, and governance processes across hybrid environments. You will also handle Level 3 Engineering and Support escalations.

Responsibilities

Identity Lifecycle Management

  • Implement and manage provisioning, de-provisioning, and access certification processes.
  • Support joiner/mover/leaver workflows and self-service access requests.

Authentication & Authorization

  • Configure and maintain Entra ID (Azure AD) for hybrid identity scenarios.
  • Manage on-prem Active Directory and integrate with cloud identity solutions.
  • Develop and enforce Conditional Access Policies and MFA strategies.

Identity Governance

  • Deploy and manage Saviynt IGA for access governance, risk analytics, and compliance.
  • Standardize identity governance across applications and business processes.

Privileged Access Management

  • Implement and maintain CyberArk for vaulting, password rotation, and privileged session management.
  • Ensure compliance with least privilege principles and break-glass account policies.

Automation & Integration

  • Develop PowerShell scripts for user provisioning, group management, and automation tasks.
  • Integrate IAM workflows with ServiceNow for access requests and approvals.

Security & Compliance

  • Conduct regular access reviews and entitlement certifications.
  • Ensure adherence to IAM standards and regulatory requirements.

Support & Engineering

  • Assist in resolving escalated support tickets routed to the IAM/IGA support queues.
  • Engineer and support identity object hygiene and cleanup efforts across AD/AAD.

Special Projects

  • Support special projects requiring IAM/IGA engineering resources.
  • Review and update design and support documentation.

Requirements

  • Strong knowledge of Entra ID (Azure AD) and hybrid identity management.
  • Hands-on experience with on-prem Active Directory administration.
  • Expertise in Saviynt IGA platform for identity governance.
  • Proficiency in CyberArk for privileged access management.
  • Familiarity with ServiceNow for IAM workflow integration.
  • Advanced scripting skills in XML, JSON, APIs, and PowerShell for automation.
  • Understanding of RBAC, ABAC, and least privilege principles.
  • Experience with compliance frameworks and audit processes.
  • Proficiency at creating, reviewing, and updating technical documentation and support articles.

Preferred Qualifications

  • 5+ years of IAM/IGA experience in large-scale enterprise environments with complex identity ecosystems.
  • Certifications: Microsoft Certified - Identity and Access Administrator, CyberArk Defender, or Saviynt Certified Professional.

Benefits

  • Parental & Family Support: 12 weeks of fully paid parental leave, fertility coverage via Progyny, and adoption/surrogacy support. Backup child and adult care are also available.
  • Healthcare: Multiple PPO and HSA medical options, including telemedicine, second-opinion services, and mental health access through Spring Health.
  • Retirement & Savings: 401(k) with a competitive employer match, additional company retirement contributions after one year of service, and an employee stock purchase plan.

Company Culture

We are a global industrial technology innovator focused on software-powered workflow solutions, data-driven intelligence, and AI-powered automation. We operate with a startup spirit, utilizing a proven business system to accelerate positive impact across environmental, health, safety, and healthcare sectors. We are a diverse team united by an inclusive culture and energized by continuous learning and growth.

Required Skills:
Azure AD / Entra IDCyberArkHashiCorp VaultSaviyntActive DirectoryRole-Based Access Control (RBAC)Attribute-Based Access Control (ABAC)Lifecycle ManagementAccess Reviews & CertificationNIST
Certifications:
CyberArk Defender
Benefits:
Parental leaveHealth insurance401k matchingPension contribution
Category:
Related IAM Topics:

Share:

Promote
  • Location


    India, IN
  • Job Type


    Full Time
  • Work Mode


    Hybrid
  • Experience


    Mid Level
  • Posted


    Jun 19, 2026
Ad
Favicon

 

  
 
Visit Workday